Gentoo Archives: gentoo-dev

From: Sebastian Werner <sebastian@××××××××××××××××××.de>
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] Secure Gentoo
Date: Wed, 06 Mar 2002 12:56:39
Message-Id: 2RM954X4Y43311VD8CFBUOUSB6LF42.3c8665a0@wp
In Reply to: [gentoo-dev] Secure Gentoo by Joachim Blaabjerg
1 This is great really great. I have not really much time to play with this. But I
2 could help you in parts of to do work. Contact me and we could do it.
3
4 I think it's enough to create acl's for the basesystem and some special
5 server apps. All these kde and gnome apps must not be installed on a real
6 server I think - so you need no acl's here.
7
8 Greetings
9
10 Sebastian
11
12 Am 06.03.2002 18:43:28, schrieb Joachim Blaabjerg <styx@×××××.org>:
13
14 >Hi again, people,
15 >
16 >If you don't have any further ideas/thoughts/objections/whatever, I'll
17 >finally start working on Secure Gentoo (or whatever the name is) now.
18 >I've had a few time problems lately, so I'm sorry I haven't got started
19 >earlier.
20 >
21 >What I'm going to do:
22 >* Make a profile with a small (minimal) set of apps, and slowly expand
23 >it as I get more packages done/patched.
24 >* Make a kernel patch, probably based on the Gentoo kernel, but with
25 >GrSecurity, kerneli, a few netfilter patches etc.
26 >* Patch packages with patches from the Owl GNU/*/Linux project (of which
27 >I am lucky to be a currently idling developer), and make ACLs for each
28 >app.
29 >
30 >My original intent was to use LIDS, but I've somewhat changed my mind.
31 >The ACL system in grsec has matured greatly lately, and I'm trying it
32 >out as we speak. Have any of you got any experiences or thoughts on this
33 >you want to share?
34 >
35 >I've got a few questions, too:
36 >Will the Gentoo kernel use Andrea Arcangeli's VM or Rik van Riel's (-aa
37 >or rmap)?
38 >How will this be done practically? I'm thinking in particular about the
39 >freeze, and the proposed unstable branch.
40 >How paranoid should it be? My first plan was to create ACLs for each and
41 >every binary and deny almost everything else, but that might be too
42 >paranoid for most people. What do you think? How about three security
43 >levels (no ACLs, normal ACLs and very strict ACls)?
44 >
45 >Any other thoughts and ideas will be greatly appreciated :)
46 >
47 >--
48 >Joachim Blaabjerg
49 >styx@×××××.org
50 >www.SuxOS.org
51 >
52 >_______________________________________________
53 >gentoo-dev mailing list
54 >gentoo-dev@g.o
55 >http://lists.gentoo.org/mailman/listinfo/gentoo-dev
56 >

Replies

Subject Author
Re: [gentoo-dev] Secure Gentoo Joachim Blaabjerg <styx@×××××.org>